Glossary · term

Claude Mythos

Claude Mythos is Anthropic's limited-access family of general-purpose frontier models for high-capability cybersecurity and biology research. The name covers successive releases, beginning with Claude Mythos Preview and continuing through Mythos 5 and Mythos 5.1; it should not be read as one unchanged model. Current Mythos versions are offered only to approved organizations under controlled-access programs, while related Fable models use the same underlying model with additional safeguards in sensitive domains.

Products2026-04-07Wave 3 · 2025–26Maturity: 3/5

Origin and context

Anthropic launched Mythos Preview and Project Glasswing on 7 April 2026, initially giving selected critical-software organizations access for defensive work. Mythos 5 succeeded Preview on 9 June, and Mythos 5.1 was designated on 31 August and announced on 1 September. The Preview API model is now deprecated in favor of Mythos 5. The intervening access interruption and later restoration also show that availability is a policy state, not an intrinsic model property.

Sources: s1, s2, s3, s4

Why it matters

Mythos is a concrete example of a restricted frontier-model release in which eligibility, safeguards, retained monitoring data and deployment context are part of the product boundary. AISI independently found that Preview improved substantially on controlled cyber challenges and completed one multi-stage simulated range in some runs. AISI also stressed that the range lacked active defenders and other real-world protections. CETaS similarly treated some claims as corroborated while warning that the full picture remained incomplete.

Sources: s3, s5, s6

Example

A model-governance analyst comparing release strategies could record the exact Mythos version, approved access route, enabled safeguards, retention terms, network permissions and evaluation environment before interpreting a result. A defensive security team should use any such model only on systems it is explicitly authorized to test, within hardened containment and human-controlled disclosure and remediation workflows. The glossary entry explains those boundaries; it is not an access guide or an operational security playbook.

Sources: s2, s3, s9

How it differs

Frontier Models

Frontier models are a broad capability category. Claude Mythos is one named commercial model family with versioned releases and restricted access conditions.

Frontier Safety Roadmap (FSR)

A frontier safety roadmap is an organizational planning artifact. Mythos is a deployed model family whose release and monitoring controls can be assessed against such plans.

AI safety institutes

AI Safety Institutes are public evaluation bodies. The UK AISI independently tested Mythos Preview; the institute and the model are not parts of one product.

Agent sandboxes

Agent sandboxes are containment environments. Mythos evaluations show why a model's capabilities and the permissions or isolation of its harness must be described separately.

Maturity and evidence

Maturity is 3. Mythos has progressed beyond a single preview into a documented family with two later releases, version migration, defined limited-access programs, current pricing and retention rules, partner use, system cards, independent government evaluation and sustained reporting. It is not rated higher because access remains narrow, the product and policies are changing quickly, current-version results are still largely vendor-reported, and safety investigations following evaluation incidents remain open.

Sources: s1, s3, s4, s5, s7, s9, s10

Limits and open questions

Most detailed capability claims come from Anthropic. AISI's independent results concern Mythos Preview under high-token-budget, controlled conditions and do not prove success against well-defended production systems; they cannot be transferred automatically to Mythos 5 or 5.1. Reports that a model found flaws within hours do not establish that it exploited them. Access, geography, safeguards, pricing and retention can change. Because the family has dual-use cyber and biology capabilities, the page must avoid procedural attack or biological guidance and must not portray restricted access, monitoring or sandboxing as a guarantee of safe behavior.

Sources: s1, s5, s6, s8, s9, s10

Related terms

References

Last updated: 2026-09-07

In the Skills Atlas

This term is also covered in the Skills Atlas as model evaluation skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as adversarial ai testing skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as agent sandboxing skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as ai risk management skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as software testing skill.